arXiv:2412.01127cs.IR2024-12被引 2

用影响函数精准定位污染项,提升序列推荐攻击效果

Precision Profile Pollution Attack on Sequential Recommenders via Influence Function

  • 基于影响函数计算污染项对模型的修正量,更准确估计影响
  • 在5个真实数据集上均超越基线,对热门与冷门商品都有效
  • 适合研究推荐系统安全或对抗攻击的读者

序列推荐方法在建模用户偏好方面表现出色,但易受用户画像污染攻击(PPA)影响,即通过向用户交互历史中插入特定项目来操纵推荐结果。由于对每个污染项重新训练模型耗时过长,现有攻击方法依赖梯度方向估算项目影响,但实际项目表征与梯度差异显著,导致评估失准。为此,我们提出基于影响函数的攻击方法INFAttack,通过计算引入特定项目后对原始模型参数的修正量,精准估计污染项影响。随后选择被最显著影响的序列替换原序列,以促进目标项目的推荐。在五个真实世界数据集上的全面实验表明,INFAttack优于所有基线方法,且对热门与冷门项目均保持稳定攻击性能。

原文摘要 · Abstract (English)

Sequential recommendation approaches have demonstrated remarkable proficiency in modeling user preferences. Nevertheless, they are susceptible to profile pollution attacks (PPA), wherein items are introduced into a user's interaction history deliberately to influence the recommendation list. Since retraining the model for each polluted item is time-consuming, recent PPAs estimate item influence based on gradient directions to identify the most effective attack candidates. However, the actual item representations diverge significantly from the gradients, resulting in disparate outcomes.To tackle this challenge, we introduce an INFluence Function-based Attack approach INFAttack that offers a more accurate estimation of the influence of polluting items. Specifically, we calculate the modifications to the original model using the influence function when generating polluted sequences by introducing specific items. Subsequently, we choose the sequence that has been most significantly influenced to substitute the original sequence, thus promoting the target item. Comprehensive experiments conducted on five real-world datasets illustrate that INFAttack surpasses all baseline methods and consistently delivers stable attack performance for both popular and unpopular items.

推荐系统对抗攻击影响函数

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。